MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fe566a1a80377c83d265df10ad45292a91a2d1a4c91a24f3082b09377f24d4ea. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry


Intelligence File information 3 Yara Comments

SHA256 hash: fe566a1a80377c83d265df10ad45292a91a2d1a4c91a24f3082b09377f24d4ea
SHA3-384 hash: f9bcc1ec3a03b65cd29139720c305405774e8811523ccb2f302a317403e8aac429ed4160f9edd8f21c984af7753d9fbf
SHA1 hash: 910554822e540400617c647dc209bae792dc34df
MD5 hash: 09ee4b57ee88b6bcaa5e06b75cc03467
humanhash: mockingbird-moon-fanta-leopard
File name:fddr_2782.xls
Download: download sample
Signature TrickBot
File size:982'528 bytes
First seen:2020-07-01 00:02:32 UTC
Last seen:2020-07-01 01:01:21 UTC
File type:Excel file xls
MIME type:application/vnd.ms-excel
ssdeep 24576:WZ5dLWgv9SLIQTui1QDRRO5sY7YnSi6+wYmTDlA:wdigv9QTui1QtRE7YnS4MTZA
TLSH 2725CEC5EFA6DA65CA81C1708F8746D02B01FD001931478B36C1B7377FAEAB4AD9A4D9
Reporter @0xCARNAGE
Tags:TrickBot

Intelligence


Mail intelligence No data
# of uploads 2
# of downloads 39
Origin country US US
ClamAV TwinWave.EvilDoc.Excel4SetNameBangYourHead.20200628.UNOFFICIAL
CERT.PL MWDB Detection:n/a
Link: https://mwdb.cert.pl/sample/fe566a1a80377c83d265df10ad45292a91a2d1a4c91a24f3082b09377f24d4ea/
ReversingLabs :Status:Benign
Threat name:No data
First seen:2020-07-01 00:04:05 UTC
AV detection:No data
Trust factor:
Hatching Triage Score:   1/10
Malware Family:n/a
Link: https://tria.ge/reports/200701-1xncww2s5x/
Tags:n/a
VirusTotal:Virustotal results 1.64%

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

TrickBot

Excel file xls fe566a1a80377c83d265df10ad45292a91a2d1a4c91a24f3082b09377f24d4ea

(this sample)

d3cb7f5846a8e827b13654e44545a3ad

  
Dropping
MD5 d3cb7f5846a8e827b13654e44545a3ad
  
Delivery method
Distributed via e-mail attachment

Comments